Vulnerability record · CVE-2023-46262 · published 19 December 2023
CVE-2023-46262: Ivanti Avalanche Remote Control server unauthenticated SSRF
Ivanti · Avalanche
Ivanti Avalanche Remote Control server is vulnerable to server-side request forgery (CWE-918) triggered by a specifically crafted web request. Because the request requires no authentication, any network-reachable attacker can make the server issue requests on their behalf, which matters for internal network reconnaissance and access to services not otherwise exposed.
Description
An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Control server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable SSRF with high confidentiality impact and a very high EPSS score, though no confirmed exploitation or KEV listing.
What it is
Ivanti Avalanche Remote Control server is vulnerable to server-side request forgery (CWE-918) triggered by a specifically crafted web request. Because the request requires no authentication, any network-reachable attacker can make the server issue requests on their behalf, which matters for internal network reconnaissance and access to services not otherwise exposed.
Impact
An attacker can cause the Avalanche server to send requests to arbitrary destinations, potentially reaching internal-only services and disclosing information from them. The CVSS vector rates confidentiality impact as high with no integrity or availability impact.
Attack surface
Reached over the network via a crafted web request to the Remote Control server; the CVSS vector (AV:N/PR:N/UI:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no public exploit or exploitation tags appear in the references, but EPSS is very high (0.82846, 99.65th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Upgrade Ivanti Avalanche to version 6.4.2 or later per the vendor release notes, which is the only remediation detail provided in the record.
- Restrict network access to the Avalanche Remote Control server so only trusted management hosts can reach it.
- Block or monitor outbound requests from the Avalanche server to internal and unexpected destinations at the network boundary.
- Place the server behind a reverse proxy or filtering layer that rejects requests targeting internal address ranges.
Detection
- Monitor Avalanche server logs for crafted or anomalous web requests to the Remote Control endpoint.
- Alert on outbound connections from the Avalanche server to internal RFC1918 addresses or unusual external hosts.
- Baseline normal outbound traffic from the Avalanche server and flag deviations, especially short-lived or repeated requests to internal services.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt | Release Notes |
| https://download.wavelink.com/Files/avalanche_v6.4.2_release_notes.txt | Release Notes |
Track CVE-2023-46262 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-46262), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.